Key Takeaways
- Medusa ransomware grew from roughly 300 to more than 500 victims in the United States within one year, largely by purchasing network access instead of exploiting it directly.
- The increase reflects a thriving market for initial‑access brokers (IABs) who sell footholds obtained via phishing or unpatched public‑facing systems.
- FBI, CISA, and HHS issued a joint advisory outlining mitigations that target the broker supply chain: phishing‑resistant MFA, timely patching, and network segmentation.
- Implementing these controls can price Medusa’s bought access out of the market, reducing the likelihood of successful ransomware deployment.
Medusa Ransomware’s Rapid Expansion
Medusa ransomware, first identified in June 2021 as a ransomware‑as‑a‑service (RaaS) operation, has become one of the most prolific extortion groups in cybercrime. In March 2023 the gang drew public attention by posting a video of stolen files from the Minneapolis Public Schools district on its dark‑web leak site. Since then, the number of confirmed victims in the United States has risen from about 300 in March 2025 to more than 500 by April 2026, according to an updated joint advisory from the FBI, CISA, and HHS. This surge underscores Medusa’s growing reach across multiple critical‑infrastructure sectors.
Sectors Impacted by Medusa Activity
The advisory tallies victims across Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Additional concentrations appear in the medical, education, legal, and insurance fields—industries where operational disruption can have cascading consequences. Notable incidents include an attack that forced a hospital to shut down its doors, elevators, and ventilation systems, illustrating the real‑world harm that Medusa’s encryption and extortion tactics can cause.
Why Medusa Buys Access Rather Than Earns It
Unlike many ransomware crews that invest in developing their own intrusion capabilities, Medusa primarily purchases ready‑made footholds. The gang’s developers recruit initial‑access brokers (IABs)—criminal middlemen who sell compromised credentials or VPN access obtained through phishing, unpatched software, or exposed services. Medusa offers these affiliates payments ranging from $100 to $1 million for exclusive work with the group. Consequently, the rise in victim count reflects the health of the access‑broker market rather than a dramatic improvement in Medusa’s own tradecraft; when footholds are cheap and plentiful, the RaaS operation scales by buying them wholesale.
The Role of Initial‑Access Brokers in Medusa’s Campaign
IABs gain entry using the same low‑tech methods that have plagued organizations for years: credential‑harvesting phishing campaigns and exploitation of unpatched public‑facing systems such as web servers, remote‑desktop gateways, or VPN appliances. Once a broker establishes a foothold, that access is packaged and sold to ransomware affiliates like Medusa. The advisory notes that the same edge‑exploitation route used by groups such as Qilin against enterprise VPNs is the primary vector Medusa’s brokers rely on, highlighting a shared weakness across many ransomware ecosystems.
Mitigation Strategy: Blocking the Foothold Market
To undermine Medusa’s business model, the joint advisory recommends a three‑pronged defensive approach that attacks the broker supply chain at its source. First, organizations should require phishing‑resistant multifactor authentication (MFA) on every remote‑access pathway. Because broker footholds typically begin with a phished or reused credential, MFA that resists credential‑theft (e.g., FIDO2 security keys or certificate‑based authentication) dramatically raises the cost for attackers. Second, timely patching of operating systems, firmware, and exposed applications removes the vulnerabilities brokers exploit to gain initial access. The advisory provides a specific patching schedule prioritizing critical internet‑facing assets. Third, network segmentation combined with strict controls on internal remote services ensures that, even if a broker’s foothold penetrates the perimeter, lateral movement is contained to a isolated segment rather than spreading domain‑wide.
Practical Steps for Implementing Phishing‑Resistant MFA
Deploying phishing‑resistant MFA involves inventorying all remote‑access vectors—VPNs, web portals, cloud consoles, and privileged‑access workstations—and replacing legacy SMS or one‑time‑password methods with hardware‑based tokens or public‑key credentials. Organizations should also enforce MFA for administrative accounts and service accounts that interact with critical systems. Continuous monitoring for MFA bypass attempts and user education about phishing tactics further strengthen this control layer.
Patch Management Best Practices Aligned with the Advisory
Effective patch management begins with maintaining an accurate asset inventory that includes all internet‑facing devices and applications. Vulnerability scans should be conducted at least weekly, with critical patches applied within 48 hours of release for high‑risk exposures. For legacy systems that cannot be immediately patched, compensating controls such as web‑application firewalls, intrusion‑prevention systems, or restricted access rules should be employed until a upgrade path is feasible.
Network Segmentation Techniques to Contain Breaches
Segmentation can be achieved through VLANs, software‑defined networking, or zero‑trust micro‑segmentation policies that enforce least‑privilege access between workloads. Critical assets such as patient‑record databases, industrial‑control systems, or financial transaction platforms should reside in isolated zones with strict firewall rules permitting only approved protocols and ports. Additionally, disabling unnecessary remote‑service protocols (e.g., SMBv1, Telnet) and enforcing jump‑host models for administrative access reduces the attack surface that a bought foothold can exploit.
Conclusion: Pricing Medusa’s Access Out of the Market
The Minneapolis stolen‑data video that first announced Medusa’s presence in 2023 has since been eclipsed by a leak site listing more than 500 organizations, each compromised via a foothold that these mitigations would have rendered uneconomical for brokers to sell. By adopting phishing‑resistant MFA, rigorous patching, and robust network segmentation, organizations not only protect themselves but also shrink the market for the initial‑access brokers that fuel Medusa’s ransomware‑as‑a‑service model. In doing so, they raise the cost of entry for cybercriminals and contribute to a broader decline in successful ransomware campaigns across critical infrastructure sectors.

